CVE-2012-5781
Amazon Elastic Load Balancing API Tools - Man-in-the-Middle Attack via Unverified X.509 Certificate
Title source: llmDescription
Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default JDK X509TrustManager.
References (1)
Core 1
Core References
Exploit x_refsource_misc
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
Scores
EPSS
0.0013
EPSS Percentile
32.8%
Details
CWE
CWE-20
Status
published
Products (10)
amazon/elastic_load_balancing
amazon/elastic_load_balancing
1.0 (2 CPE variants)
amazon/elastic_load_balancing
1.0.3.4
amazon/elastic_load_balancing
1.0.9.3
amazon/elastic_load_balancing
1.0.10.0
amazon/elastic_load_balancing
1.0.11.1
amazon/elastic_load_balancing
1.0.12.0
amazon/elastic_load_balancing
1.0.14.3
amazon/elastic_load_balancing
1.0.15.1
amazon/elastic_load_balancing
1.0.17.0
Published
Nov 04, 2012
Tracked Since
Feb 18, 2026